CVE-2025-14881

EUVD-2025-204530
Multiple API endpoints allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
rami.ioCNA
3.8 LOW
NETWORK
LOW
LOW
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:U
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
pretixpretix
1.0.0 ≤
𝑥
< 2025.8.0
CNA
pretixpretix
2025.8.0 ≤
𝑥
< 2025.9.0
CNA
pretixpretix
2025.9.0 ≤
𝑥
< 2025.10.0
CNA
pretixpretix
2025.10.0 ≤
𝑥
< 2025.11.0
CNA